The European AI Act did not apply all at once. It has a staged calendar spread over several years, and in 2026 some of the deadlines moved. For an ordinary company, all that matters is knowing what is already active, what is coming, and what applies to you.

Below is the calendar in short, then what each stage means in practice.

The calendar in short

  • 1 Aug 2024 The Regulation enters into force. No obligations apply yet.
  • 2 Feb 2025 The prohibitions on banned AI practices and the AI literacy obligation (Article 4) start to apply.
  • 2 Aug 2025 The rules for general-purpose AI models (GPAI), governance, and part of the penalties start to apply.
  • 2 Dec 2026 New prohibitions take effect on AI-generated non-consensual intimate imagery and child sexual abuse material.
  • 2 Dec 2027 The obligations for high-risk systems under Annex III apply (deferred from August 2026).
  • 2 Aug 2028 The obligations for high-risk systems embedded in regulated products (Annex I) apply.

What already applies

Two deadlines have already passed, and they apply to you even if you only use AI rather than build it.

Since 2 February 2025, certain AI practices such as social scoring or manipulation are banned, and the Article 4 AI literacy obligation is active. If your employees use AI at work, you have to make sure they know what they are doing, and you have to be able to show what steps you took. We covered this in the article on AI literacy for employees.

Since 2 August 2025, the rules for general-purpose models, EU-level governance, and part of the penalty regime apply. Most companies are touched by this indirectly, through the model providers they use, rather than directly.

What was deferred in 2026

The most-discussed change in 2026 is the deferral of the obligations for high-risk systems. Through a simplification package called the Digital Omnibus, the deadline for Annex III systems moved from August 2026 to 2 December 2027, and the one for systems embedded in regulated products (Annex I) to 2 August 2028.

Deferred does not mean cancelled. The obligations stay the same — conformity assessments, documentation, human oversight — you just have more time to prepare. If you use AI in a sensitive area such as hiring, credit decisions, health, or safety, you still land in the high-risk category.

What it means for your company

Most companies are not AI model providers and do not operate high-risk systems. For them, the priority list is short:

  • AI literacy. The Article 4 obligation is already active. It has no exemption threshold and no deferral, so it is the first thing a review would check.
  • An inventory of AI use. Which tools the teams use and for what, so you know where you stand.
  • A risk classification. Check whether any use falls into the high-risk or prohibited zone, so you are not caught unprepared by the 2027 deadlines.

This is a summary, not legal advice. For a specific case, check the official text of the Regulation or ask an advisor.

Frequently asked questions

When does the EU AI Act take effect for companies?
It applies in stages. The prohibitions and the AI literacy obligation have been in force since 2 February 2025; the rules for general-purpose AI models, governance, and part of the penalties since 2 August 2025; and the obligations for high-risk systems under Annex III from 2 December 2027.

Have the EU AI Act deadlines been postponed?
Yes, in part. Through a package called the Digital Omnibus, the obligations for high-risk systems under Annex III were moved from August 2026 to 2 December 2027, and those under Annex I to 2 August 2028. The other deadlines are unchanged.

How large are the EU AI Act fines?
Fines can reach up to 35 million euros or 7% of global annual turnover for prohibited practices, with lower thresholds for other breaches.